First published: Thu Aug 04 2016(Updated: )
A regression was found on RHEL-5.11 making apr-util and httpd vulnerable to billion laughs attack, also known as <a href="https://access.redhat.com/security/cve/CVE-2009-1955">CVE-2009-1955</a>, again.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Linux | =5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6312 is considered a medium severity vulnerability as it introduces a potential denial-of-service condition.
To fix CVE-2016-6312, you should upgrade to a patched version of RHEL or the affected Apache modules that address this vulnerability.
CVE-2016-6312 specifically affects Red Hat Enterprise Linux version 5.11 that uses the apr-util and httpd components.
CVE-2016-6312 is associated with the billion laughs attack, a form of denial-of-service attack that exploits XML processing.
CVE-2016-6312 is a regression vulnerability that reopens previously addressed issues from CVE-2009-1955.